[PATCH v2 09/13] security/keys: implement wipe op for asymmetric keys

Jan Sebastian Götte <[email protected]>
Newsgroups org.infradead.lists.linux-nvme,dev.linux.lists.dm-devel,org.infradead.lists.kexec,org.kernel.vger.keyrings,org.kernel.vger.linux-crypto,org.kernel.vger.linux-doc,org.kernel.vger.linux-fscrypt,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-integrity,org.kernel.vger.linux-kernel,org.kernel.vger.linux-nfs,org.kernel.vger.linux-security-module,org.kernel.vger.netdev,org.kvack.linux-mm
Message-ID <[email protected]>
Add wipe op to the subtype and implement it for public_key.

Used by CONFIG_CRASH_WIPE_SECRETS.

Signed-off-by: Jan Sebastian Götte <[email protected]>
---
 crypto/asymmetric_keys/asymmetric_type.c | 11 +++++++++++
 crypto/asymmetric_keys/public_key.c      | 15 +++++++++++++++
 include/keys/asymmetric-subtype.h        |  5 +++++
 3 files changed, 31 insertions(+)

diff --git a/crypto/asymmetric_keys/asymmetric_type.c b/crypto/asymmetric_keys/asymmetric_type.c
index 16a7ae16593c..a0a68ebd0746 100644
--- a/crypto/asymmetric_keys/asymmetric_type.c
+++ b/crypto/asymmetric_keys/asymmetric_type.c
@@ -481,6 +481,16 @@ static void asymmetric_key_destroy(struct key *key)
 	asymmetric_key_free_kids(kids);
 }
 
+/* wipe the key without freeing. used by CONFIG_CRASH_WIPE_SECRETS. */
+static void asymmetric_key_wipe(struct key *key)
+{
+	struct asymmetric_key_subtype *subtype = asymmetric_key_subtype(key);
+
+	if (subtype && subtype->wipe)
+		subtype->wipe(key->payload.data[asym_crypto],
+				key->payload.data[asym_auth]);
+}
+
 static struct key_restriction *asymmetric_restriction_alloc(
 	key_restrict_link_func_t check,
 	struct key *key)
@@ -612,6 +622,7 @@ struct key_type key_type_asymmetric = {
 	.match_preparse		= asymmetric_key_match_preparse,
 	.match_free		= asymmetric_key_match_free,
 	.destroy		= asymmetric_key_destroy,
+	.wipe			= asymmetric_key_wipe,
 	.describe		= asymmetric_key_describe,
 	.lookup_restriction	= asymmetric_lookup_restriction,
 	.asym_query		= query_asymmetric_key,
diff --git a/crypto/asymmetric_keys/public_key.c b/crypto/asymmetric_keys/public_key.c
index 09a0b83d5d77..9931d56337e5 100644
--- a/crypto/asymmetric_keys/public_key.c
+++ b/crypto/asymmetric_keys/public_key.c
@@ -13,6 +13,7 @@
 #include <crypto/sig.h>
 #include <keys/asymmetric-subtype.h>
 #include <linux/asn1.h>
+#include <linux/crash_core.h>
 #include <linux/err.h>
 #include <linux/kernel.h>
 #include <linux/module.h>
@@ -58,6 +59,19 @@ static void public_key_destroy(void *payload0, void *payload3)
 	public_key_signature_free(payload3);
 }
 
+/* wipe the key without freeing. used by CONFIG_CRASH_WIPE_SECRETS. */
+static void public_key_wipe(void *payload0, void *payload3)
+{
+	struct public_key *key = payload0;
+
+	if (key) {
+		if (key->key)
+			crash_wipe_memzero(key->key, key->keylen);
+		if (key->params)
+			crash_wipe_memzero(key->params, key->paramlen);
+	}
+}
+
 /*
  * Given a public_key, and an encoding and hash_algo to be used for signing
  * and/or verification with that key, determine the name of the corresponding
@@ -464,6 +478,7 @@ struct asymmetric_key_subtype public_key_subtype = {
 	.name_len		= sizeof("public_key") - 1,
 	.describe		= public_key_describe,
 	.destroy		= public_key_destroy,
+	.wipe			= public_key_wipe,
 	.query			= software_key_query,
 	.eds_op			= software_key_eds_op,
 	.verify_signature	= public_key_verify_signature_2,
diff --git a/include/keys/asymmetric-subtype.h b/include/keys/asymmetric-subtype.h
index d55171f640a0..17c74070c101 100644
--- a/include/keys/asymmetric-subtype.h
+++ b/include/keys/asymmetric-subtype.h
@@ -32,6 +32,11 @@ struct asymmetric_key_subtype {
 	/* Destroy a key of this subtype */
 	void (*destroy)(void *payload_crypto, void *payload_auth);
 
+	/* Wipe a key of this subtype without freeing it (optional).  Used by
+	 * CONFIG_CRASH_WIPE_SECRETS from the panic path.
+	 */
+	void (*wipe)(void *payload_crypto, void *payload_auth);
+
 	int (*query)(const struct kernel_pkey_params *params,
 		     struct kernel_pkey_query *info);
 

-- 
2.53.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.